Strategic IT Security & GRC Leader

HS2 (High Speed Two) Ltd

Birmingham

Hybrid

GBP 59,000 - 72,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible benefits fund 20%
Flexible working
Personal and professional development

Job summary

HS2 Ltd is seeking a Principal IT Security Manager (GRC) to lead governance, risk and compliance within the Information & Cyber Security function. You will shape enterprise-wide security policies, manage third-party risk and oversee testing and assurance activities to protect critical systems.

The role requires translating business goals into security requirements, collaborating with legal, procurement and IT teams, and delivering executive risk reporting.

Qualifications

  • Experience with governance, risk and compliance within information security.
  • Ability to translate business goals into cyber governance requirements.
  • Knowledge of NCSC standards and Cabinet Office requirements.
  • Experience with third‑party risk management and supplier contracts.
  • Experience with security testing and assurance strategies.
  • Experience with risk management and audit remediation.

Responsibilities

  • Direct the development, implementation and maintaining organisation wide cybersecurity governance frameworks.
  • Own the enterprise wide Information & Cyber Security policy lifecycle, ensuring regular review, approval, and publication of security policies.
  • Defining, managing and maintaining security policies, standards, procedures and controls aligned with regulatory requirements.
  • Translate business goals into cyber governance requirements and embed into third-party and internal delivery frameworks.
  • Oversee the provision of security testing and assurance strategy and capability, including penetration testing and simulation exercises.
  • Own the information and cyber risk register and track mitigation progress.
  • Set direction for enterprise-wide risk assessment methodologies and ensure integration with corporate risk processes.
  • Lead the third-party risk management program, including vendor due diligence and ongoing monitoring.
  • Work with procurement, legal, and IT to embed security clauses in supplier contracts.
  • Maintain a risk profile for critical suppliers and support risk treatment or exit strategies.
  • Ensure ongoing compliance with cybersecurity-related legal, regulatory, and contractual obligations.
  • Manage responses to audits and reporting of KRIs.

Skills

Governance
Governance & Assurance
Problem definition
Stakeholder communication
Team management
GRC knowledge
Cybersecurity frameworks
Security testing
Public sector standards

Job description

HS2 Ltd is seeking a Principal IT Security Manager (GRC) to lead governance, risk and compliance within the Information & Cyber Security function. You will shape enterprise-wide security policies, manage third-party risk and oversee testing and assurance activities to protect critical systems.

The role requires translating business goals into security requirements, collaborating with legal, procurement and IT teams, and delivering executive risk reporting.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security & GRC Leader: Governance & Risk
IT Security & GRC Leader: Governance & Risk

HS2 (High Speed Two) • Birmingham

On-site
GBP 59,000 - 72,000
Flexible benefits 20%
Principal IT Security Manager (GRC)
Principal IT Security Manager (GRC)

HS2 (High Speed Two) Ltd • Birmingham

Hybrid
GBP 59,000 - 72,000
Flexible benefits fund 20%
Flexible working
Personal and professional development
Security Architect & GRC Lead
Security Architect & GRC Lead

LHH • Scotland

On-site
GBP 90,000 - 130,000
Principal IT Security Manager (GRC)
Principal IT Security Manager (GRC)

HS2 (High Speed Two) • Birmingham

On-site
GBP 59,000 - 72,000
Flexible benefits 20%
Information Security Specialist
Information Security Specialist

Michael James Associates • Greater London

On-site
GBP 90,000 - 120,000
Senior Information Security (GRC) Specialist
Senior Information Security (GRC) Specialist

La Fosse • Greater London

Hybrid
GBP 81,000 - 99,000
Pension
Benefits
Senior InfoSec GRC Lead — Hybrid, Equity Eligible
Senior InfoSec GRC Lead — Hybrid, Equity Eligible

BMS Group • Greater London

Hybrid
GBP 90,000 - 130,000
27 days holiday
Bonus scheme
Private medical cover
+2
IT GRC Senior Analyst
IT GRC Senior Analyst

Nigel Wright Recruitment • Newcastle upon Tyne

Hybrid
GBP 70,000 - 90,000
Hybrid work policy
Security & GRC Lead: Cyber Risk, Audit & Compliance
Security & GRC Lead: Cyber Risk, Audit & Compliance

Amiqus • United Kingdom

On-site
GBP 60,000 - 85,000
Senior GRC Specialist: Transform Governance & Risk
Senior GRC Specialist: Transform Governance & Risk

La Fosse Associates • Greater London

Hybrid
GBP 54,000 - 90,000
Pension